blob: abb193fe79b0503f265fb846ffe3cf77adce09b6 [file] [log] [blame]
Victor Hsieha62b3ff2022-05-02 09:47:11 -07001system_restricted_prop(boot_status_prop)
2
Victor Hsiehb415c732021-12-14 11:06:23 -08003# Declare ART properties for CompOS
4system_public_prop(dalvik_config_prop)
5system_restricted_prop(device_config_runtime_native_prop)
6
Inseob Kim5ee61a72021-09-17 19:31:45 +09007# Don't audit legacy ctl. property handling. We only want the newer permission check to appear
8# in the audit log
9dontaudit domain {
10 ctl_console_prop
11 ctl_default_prop
12 ctl_fuse_prop
13}:property_service set;
14
Inseob Kime1389972021-07-19 07:48:34 +000015###
16### Neverallow rules
17###
18
Jiyong Park27bb6c62021-09-06 15:39:31 +090019# microdroid_manager_roothash_prop can only be set by microdroid_manager
20# and read by apkdmverity
21neverallow {
22 domain
23 -init
24 -microdroid_manager
25} microdroid_manager_roothash_prop:property_service set;
26
27neverallow {
28 domain
29 -init
30 -microdroid_manager
31 -apkdmverity
32} microdroid_manager_roothash_prop:file no_rw_file_perms;
Richard Fung0c7c2672021-11-08 20:09:54 +000033
34# apexd_payload_metadata_prop can only set by init
35neverallow {
36 domain
37 -init
38} apexd_payload_metadata_prop:property_service set;